Closed MikeHofmann closed 2 years ago
It looks like your images are missing the NTFS back-up volume header. Are these images of a volume created by a live imaging tool on Windows? Are you sure your imaging tool includes the full volume and not silently skips the last sector?
Have a look at https://github.com/libyal/libbfoverlay/wiki/Examples#correcting-truncated-windows-live-volume-images to see if that can help work-around the missing data
Possibly related https://github.com/log2timeline/dfvfs/issues/514
Are these images of a volume created by a live imaging tool on Windows?
One was done with AccessData® FTK® Imager 4.5.0.3
the other with Logicube Falcon-Neo 3.1
. I doubt that these two are affected, especially the Falcon-Neo was done offline as its a hardware-imager.
I'll try some of the recovery tips from your link later in the week.
I doubt that these two are affected, especially the Falcon-Neo was done offline as its a hardware-imager.
any other reasons why the backup volume header could be missing?
Description of problem:
We have two images (from different aquisition tools, differents systems, different examiner) which fail to be parsed with log2timeline.py. Shortly after starting the process, the following error is given:
We tried different tools to convert the image files (from EWF to EWF, from EWF to RAW) and retry parsing without success. Both images open with XWays without trouble. Also tried
--no_vss
without success.Command line and arguments:
log2timeline.py --workers 1 --debug timeline.plaso /redactedt/62_redacted/redacted.E01
Source data:
Please provide the source data you used when you experienced the problem. For publicly available data please provide an URL or path of the source data.
Plaso version:
Operating system Plaso is running on:
Installed using latest docker image
Installation method:
Installed using latest docker image
Debug output/tracebacks:
logfile just contains one line: